KnowBe4 incident

PhishER Access Issue for UK/CA Instances

Major Resolved View vendor source →

KnowBe4 experienced a major incident on April 20, 2026 affecting Console, lasting 3h 31m. The incident has been resolved; the full update timeline is below.

Started
Apr 20, 2026, 03:18 PM UTC
Resolved
Apr 20, 2026, 06:50 PM UTC
Duration
3h 31m
Detected by Pingoru
Apr 20, 2026, 03:18 PM UTC

Affected components

Console

Update timeline

  1. monitoring Apr 20, 2026, 03:18 PM UTC

    We've identified the issue that was resulting in a Restricted error when attempting to access the PhishER console for UK and CA customers and have implemented a fix. Impacted users may need to refresh the page to access the PhishER console.

  2. identified Apr 20, 2026, 03:53 PM UTC

    We've identified an issue that is resulting in a Restricted error when attempting to access the PhishER console for UK and CA customers, and we are working on implementing a resolution.

  3. resolved Apr 20, 2026, 06:50 PM UTC

    We've identified an issue that resulted in a Restricted error when attempting to access the PhishER console for UK and CA customers. Our team has implemented a fix and this has now been resolved.

  4. postmortem Jun 30, 2026, 07:32 PM UTC

    On Monday, April 20, 2026, from approximately 14:00 until 20:00 \(UTC\), some customers experienced "Restricted" errors when attempting to access the PhishER console in our UK and Canada instances. This incident was caused by a configuration mismatch during a service deployment. A change in our infrastructure code inadvertently removed a required regional provider alias and upgraded a core distribution module to an unverified version. These combined factors caused regional resources to be resolved incorrectly, which prevented some users from accessing the console. Once we restored the configuration to the correct provider alias and module version, the PhishER console returned to normal performance by 20:00 \(UTC\). To prevent this type of issue in the future, we have implemented stricter rules for software versioning and improved our testing process. We’ve also updated our internal documentation and monitoring alerts to identify and respond to similar configuration errors more quickly. No data loss occurred as a result of this issue.